tencent cloud

Access Isolation by Device Type

Unduh
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-09-08 20:23:09
Diterjemahkan oleh AI

Test Objective

Applicable scenario: Terminals are typically grouped by company organizational structure, and the same applies to resource authorization.
When executing a specific project, you may need to draw employees from different departments to form a new project team, and then manage and authorize the terminals of these employees.
Each department owns some special devices that need to be managed separately.
Expected result:
When account A accesses specific resources on a terminal in a custom group, challenge authentication is triggered.
When account A accesses specific resources on another terminal, challenge authentication is not triggered.

Prerequisites

1. The iOA client is deployed successfully.
2. Complete account creation and authentication source configuration.
3. Add the business resources.
4. Complete authorization for the corresponding users and resources.

Test Examples

Step 1: Creating a Custom Group

1. Log in to the Tencent iOA Zero Trust Security Management System console and choose Terminal Management > Terminal List >  in the left sidebar.
2. On the Terminal Information page, select Custom Group and click

to add a custom group.

3. On the Add Group page, enter Basic Information and Add Terminal, then click Confirm.



4. On the Custom Group page, you can see the group you just created.


Step 2: Configuring an Authentication Policy

1. Log in to the Tencent iOA Zero Trust Security Management System console and choose Identity Security Management > Authentication Policy in the left sidebar.
2. On the Authentication Policy page, select Authentication Policy, choose a directory name, and click Add Authentication Policy.

3. Configuration example: Set the authentication source for the PC challenge authentication method to iOA local account password and click Add.


Step 3: Configuring an Access Security Policy

1. Log in to the iOA Zero Trust Management Platform console, choose Trusted Access Management > Tunnel Resource Dynamic Access, and click Add Access Policy.

2. On the Create Policy page, configure the relevant parameters. For Access Action, select Access After Challenge Authentication, choose Device Scope, and click Add This Condition.

3. Select the custom group created in Step 1 and click OK > Save.




Step 4: Terminal Verification

1. Log in with account A on a terminal in the custom group - Strategic Group, access specific resources to trigger challenge authentication, and access is granted after successful authentication.
2. When account A accesses specific resources on another terminal, challenge authentication is not triggered, and the access succeeds.


Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan